Medical IT

HIPAA and AI Tools: A Sarasota Medical Practice Checklist

AI can save administrative time. It can also create an untracked path for protected health information. Here is a practical way for small practices to decide what is acceptable before a prompt becomes a privacy incident.

AI tools are appearing in everyday clinical and administrative work: drafting a patient letter, summarizing a meeting, preparing a prior-authorization checklist, or polishing a referral. The useful question for a Sarasota practice is not whether AI is good or bad. It is whether the information entering a tool is protected by the right agreement, settings, access controls, and workflow.

HIPAA requires covered entities and business associates to protect the confidentiality, integrity, and availability of electronic protected health information (ePHI). OCR’s January 2026 cybersecurity newsletter is a timely reminder that the Security Rule is an operating responsibility, not a one-time paperwork exercise. A public consumer AI account is not automatically an approved place to put PHI simply because it is convenient.

Start with the data, not the tool

Before evaluating a chatbot, note-taking assistant, transcription service, or document helper, map what staff may paste, upload, or connect. Names, dates of birth, account identifiers, appointment details, screenshots, and free-text clinical narratives can all make a prompt sensitive. De-identification can reduce risk, but it must be deliberate; removing a patient name while leaving a rare condition, date, provider, and location may not be enough for the intended use.

That inventory belongs in the same documented risk-analysis process that supports your broader HIPAA compliance program. It should identify where ePHI lives, who can access it, how it travels, and what happens if a staff member uses an unapproved service.

Four questions before anyone uses an AI service with PHI

1. Is there a business associate agreement?

If a vendor creates, receives, maintains, or transmits ePHI on the practice’s behalf, the relationship may require a business associate agreement (BAA). HHS explains in its cloud-computing guidance that a cloud provider handling ePHI is generally a business associate even when it can only store encrypted data. Do not assume a vendor’s general terms or a privacy page substitutes for a signed BAA.

2. What does the service do with prompts and files?

Get the answer in writing: retention period, geographic processing, training use, sub-processors, administrator audit logs, and deletion options. Enterprise settings may differ materially from a free or individual account. Configure the approved environment so staff cannot casually turn on data sharing or connect a personal account.

3. Can you apply least privilege and prove it later?

Use named accounts, MFA, role-based access, and audit logs. A shared login makes an incident harder to investigate and conflicts with the accountability a medical practice needs. Managed identity through Microsoft 365 Business Premium, paired with a password manager such as 1Password, gives a small office a practical foundation without asking clinicians to become security administrators.

4. Is the output safe to use?

AI output needs human review. Treat it as a draft, not clinical advice or a final record. Establish which uses are allowed—administrative first drafts, internal policy outlines, or de-identified training examples—and which are prohibited, such as entering patient narratives into an unapproved public tool.

AI does not replace the HIPAA security basics

New tools do not make old controls less important. OCR’s Security Rule NPRM fact sheet emphasizes the national standards protecting ePHI. For a small practice, the dependable baseline remains MFA, managed endpoints, prompt patching, encrypted backups, access reviews, and staff training. Those controls also reduce the chance that a compromised email account becomes a route into your EHR, cloud files, or AI workspace.

Website tracking deserves the same care. OCR says covered entities and business associates must not impermissibly disclose PHI to tracking vendors; review the agency’s online tracking technologies guidance before adding analytics, chat, or scheduling widgets to pages that could reveal care-seeking activity.

Three things you can do this week

  1. Publish a short AI-use rule. State that staff may not enter PHI into unapproved AI services, and give them one clear person to ask before testing a new tool.
  2. Inventory existing use. Ask every department which AI, transcription, or summarization tools they use and whether any account touches patient-related information.
  3. Review access and agreements. Confirm MFA, named accounts, logging, retention settings, and a BAA where the intended workflow requires one.

Make the helpful path the safe path

Small practices should not have to choose between modern productivity and patient trust. A documented approved-tools list, sensible identity controls, and a recurring risk review make experimentation manageable. If your practice also needs a recovery plan for ransomware or an email compromise, start with our guide to ransomware protection for Florida professional firms.

Gregory Mathews, Systems Architect and founder of Suncoast MIS

Author & technical scope review

Gregory Mathews

Gregory is the Systems Architect and founder of Suncoast MIS, with 15+ years of practical IT and systems architecture experience. He authored this article and reviewed its technical scope. Compliance and legal conclusions remain with each organization and its qualified advisors.

Related Reading